STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x NDM Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

Sentry must be configured to use DOD PKI as multi-factor authentication (MFA) for interactive logins.

DISA Rule

SV-250988r1028216_rule

Vulnerability Number

V-250988

Group Title

SRG-APP-000149-NDM-000247

Rule Version

MOIS-ND-000390

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the Sentry with DOD PKI-based Certificate Authentication.

1. Log in to the Sentry System Manager.
2. Go to Security tab >> Advanced >> Sign-in Authentication.
3. Select the Certificate Authentication checkbox.
4. Select the CAC or PIV checkbox.
5. Map user certificate fields in the Certificate Attribute Mapping section based on the organization's certificates.
6. Upload the Issuing CA Certificate chain.
7. Click "Apply" and "Save" in the top right corner.
8. If using DOD PKI, ensure an EDIPI attribute is assigned to the user in the Security >> Local Users section.

Check Contents

Review the Sentry Configuration to ensure Certificate Authentication has been configured.

1. Log in to the Sentry System Manager.
2. Go to Security tab >> Advanced >> Sign-in Authentication.
3. Determine if Certificate Authentication is activated and configured.

If Certificate Authentication is not activated and configured, this is a finding.

Vulnerability Number

V-250988

Documentable

False

Rule Version

MOIS-ND-000390

Severity Override Guidance

Review the Sentry Configuration to ensure Certificate Authentication has been configured.

1. Log in to the Sentry System Manager.
2. Go to Security tab >> Advanced >> Sign-in Authentication.
3. Determine if Certificate Authentication is activated and configured.

If Certificate Authentication is not activated and configured, this is a finding.

Check Content Reference

M

Target Key

5438